SAML assertion size limit at the Assertion Consumer in Federation
search cancel

SAML assertion size limit at the Assertion Consumer in Federation

book

Article ID: 24147

calendar_today

Updated On:

Products

CA Single Sign On Secure Proxy Server (SiteMinder) CA Single Sign-On SITEMINDER CA Single Sign On Federation (SiteMinder)

Issue/Introduction

Administrators configuring SAML federation need to know whether a size limit is enforced on assertions at the Assertion Consumer Service, part of the Web Agent Option Pack or CA Access Gateway (SPS) [1], what the default value is, and where to adjust it if one exists.

Environment

  • SiteMinder Policy Server 12.8SP8 and later
  • Component: Web Agent Option Pack or CA Access Gateway (SPS) — both host the Federation Web Services Assertion Consumer Service

Resolution

The Assertion Consumer Service does not verify or enforce a size limit on SAML assertions or responses. Assertion and response size varies naturally based on the number of attributes included, the encryption algorithm used, and whether digital signatures are applied. There is no default value to adjust for this reason, since no such check exists.

This absence of a receiving-side size check is separate from the sending-side attribute length limit enforced by the Policy Server's assertion generator, which can truncate an individual attribute before the assertion is even sent. See [2] for that limit and how to adjust it.

Additional Information

  1. Configure a SAML 2.0 Service Provider

  2. "Response attribute will be trimmed" warning for SAML attributes in Federation